Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

41–50 of 168 posts

Re: How I could have hacked any Facebook account

#41
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

Hack into zuckerberg's id, get his card info if it's stored, and for fun change the profile pic, send the news to top blogs before letting Facebook know. How much it would cost Facebook to do damage control?

Re: How I could have hacked any Facebook account

#42
post #23
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

From this article I get the impression that the bounty wasn't even known before hand. It doesn't seem like a very careful consideration from Facebook, and I would expect it to be "too low" if they're choosing the amount after someone has already disclosed the bug.

Re: How I could have hacked any Facebook account

#43
post #35

Earlier quoted context omitted.

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

>Compromised user accounts (not even the server! just users!) on a single website do not constitute a valuable target.

That statement is just plain wrong. With over a billion Facebook users, surely some of them are high-value targets.

Re: How I could have hacked any Facebook account

#44
post #16

Earlier quoted context omitted.

$15k and a likely open FB job offer

> job offer Really? For brute forcing an un-rate-limited endpoint? I doubt it.

I'm sure they might encourage him to interview, but he's not going to get a serious job offer just from this. There's essentially nothing technical or skillful going on here, other than the basic coding ability to do HTTP requests in a loop and the hunch to investigate if subdomains don't rate limit.

Re: How I could have hacked any Facebook account

#45
post #35

Earlier quoted context omitted.

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

Your claim was about the severity of the bug.

It all really depends on how fast FB can service the requests and how long it takes for them to notice and shut it down. Push your priority list off to a worldwide farm and watch the accounts pop out.

How long until FB would have it shut down and the affected accounts locked out?

Re: How I could have hacked any Facebook account

#47

Earlier quoted context omitted.

2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.

There are ways around this for some things but, probably not with services like Facebook. For example with Amazon I use 2FA with a cellphone. As a backup I use a hardware token and an Admin account. If my cellphone gets stolen I pull the 2FA card out of my wallet.

Provided that nobody steals your wallet and you don't lose that card.

Re: How I could have hacked any Facebook account

#48
Regardless of this being Facebook or not, but forget to throttle your API and this is what you get, some dude toying around with a tool just to poke holes in your thing, but I digress.

If in any twisted, unrealistic, straight out of Homeland scenario where anyone high profile enough would make use of this "vulnerability" and successfully create a media "splash", and assuming Facebook security team is on top of their game, this would get patched in a week tops. Keeping an eye on average number of requests coming to their API end points, especially sensitive ones, is part of their job, not a nice-to-have. I'd even think this would actually get patched within 24 hours (since the fix isn't really that difficult). I have absolutely no care or sympathy for Facebook but yeah, 15K is a lot for something like this. It's a nice catch, that's all.

Re: How I could have hacked any Facebook account

#49
post #38

Earlier quoted context omitted.

2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.

When setting up Google Authenticator for One Time Passcodes, you are also given a seed which can be used to resteup the app from another device.

Provided you don't lose that seed. If I end up homeless will lose all my stuff and limited to library access. You have to plan for the worst case scenarios with 2FA when things go bad.

Re: How I could have hacked any Facebook account

#50

This has me thinking about another possible attack. Say I don't want to hack all of Facebook or a specific account. What if I used a botnet to reset passwords and then use the six attempts randomly on each account I reset. Sure I'd only get a small percentage but, I would easily start hacking FB accounts. It's things like this that make me use 2FA as much as possible on personal data.

2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.

Authy is really good. https://www.authy.com/

They need a Firefox extension but its allowed me to do 2FA on my personal and work accounts without fear of being totally locked out if I loose my phone.

Post reply on HN